Xeno-RAT通信模型剖析及自动化解密脚本实现
2024-05-14 • Aliyun • Xeno-RAT communication-model analysis and automated decryption script implementation •
The report analyzes Xeno-RAT as an open-source remote-access tool and builds on prior Kimsuky research involving PowerShell loading of an encrypted Xeno-RAT payload. It covers configuration extraction, feature analysis, command-and-control communication behavior, and construction of a decryption workflow, making it useful for defenders tracking Xeno-RAT tradecraft in Kimsuky-linked intrusion chains.
Indicators of Compromise
Related Actors
Related Reports
Shares tags: Kimsuky, XenoRAT • Same author: Aliyun • Published within a week
Shares tag: Kimsuky • Same author: Aliyun • Published within a month
Shares tags: Kimsuky, XenoRAT
2025-08-18 •
60% Match
#Kimsuky
#Phishing
#LNK
#XenoRAT
#T1102.002
#T1082
#T1567.002
#T1071.001
#T1112
#T1083
#T1027
#T1204.002
#T1566.002
#T1059.005
#T1566.001
#T1053.005
#T1059.001
#T1036.005
#T1105
#T1087.001
#T1106
#T1134
#T1071.004
#T1568
#T1102.003
#T1569
#T1033
#T1569.002
Shares tags: Kimsuky, XenoRAT
Shares tags: Kimsuky, XenoRAT
2025-06-19 •
60% Match
Dissecting Kimsuky's Attacks on South Korea: In-Depth Analysis of GitHub-Based Malicious Infrastructure
ENKI
Shares tags: Kimsuky, XenoRAT